FIRMWARE RELEASE NOTE ====================== Products affected: P3346 Release date: 2020-08-21 Release type: Production Firmware version: 5.51.7 Preceding release: 5.51.6.2 -------------------------------------------------------------------------------- Upgrade instructions ==================== Upgrade the firmware according to the instructions given at https://www.axis.com/ca/en/support/technical-notes/how-to-upgrade or howtoupgrade.txt, which is included in the firmware folder. NOTE ==================== For latest information about Axis Cybersecurity, see https://www.axis.com/se/sv/support/product-security. Corrections in 5.51.7 since 5.51.6.2 ===================================== 5.51.7:C01 Added possibility to retrieve the device Owner Authentication Key (OAK) in the web GUI. Note that this functionality requires that the product have direct access to the internet. 5.51.7:C02 Updated the wpa-supplicant to version 2.9 to increase the overall cybersecurity level. The following cybersecurity vulnerabilities are fixed: CVE-2019-13377 CVE-2019-16275. 5.51.7:C03 Updated OpenSSL to 1.1.1d to increase the overall cybersecurity level. 5.51.7:C04 Added support for TLSv1.2. 5.51.7:C05 Updated the client-side URL transfer library (libcurl) to version 7.53.1 to increase the overall cybersecurity level. Corrections in 5.51.6.2 since 5.51.6.1 ======================================= 5.51.6.2:C01 Corrected an issue that caused admin users other than root not to be allowed to change user account passwords. 5.51.6.2:C02 Added ProxyDispatcherOnly option to the O3C/AVHS client that can control proxy configurations of dispatcher services. 5.51.6.2:C03 Corrected an issue that caused camera to drop network connection when using 5.51.6.1 firmware. 5.51.6.2:C04 Added support for NAS over 2TB. Corrections in 5.51.6.1 since 5.51.6 ===================================== 5.51.6.1:C01 Added “X-Frame-Options: sameorigin” to the HTTP Response Headers in order to increase overall minimum cybersecurity level 5.51.6.1:C02 Updated Turkey (Istanbul) timezone to GMT +3. 5.51.6.1:C03 Improved robustness of the O3C client. Corrections in 5.51.6 since 5.51.5.2 ===================================== 5.51.6:C01 Improved robustness of the O3C client. 5.51.6:C02 Removed the root users default password in factory defaulted firmware. The password of the root user must be set first in order to initialize VAPIX and ONVIF interfaces to allow further configuration. This change only affects products in its factory defaulted state, products that are already deployed in production systems are not affected by this update until factory defaulted. Corrections in 5.51.5.2 since 5.51.5.1 ======================================= 5.51.5.2:C01 Corrected an issue that caused event notifications not been triggered on storage disruption. 5.51.5.2:C02 Improved re-connection behavior to AVHS server. The time between failed connection attempts will now gradually increase until a hard limit is reached. 5.51.5.2:C03 A user with administrator rights can now upload PTZ drivers for those cameras supporting this feature. Note that a factory default will be required to remove the old permissions sets from the firmware. 5.51.5.2:C04 Corrected an issue that caused an overload of the CPU after enabling IP adress filtering. 5.51.5.2:C05 Corrected common vulnerabilities in the Linux kernel to increase overall minimum cyber security level. CVE-2010-2960, CVE-2010-4175. 5.51.5.2:C06 Patched security vulernability CVE-2018-14526 in WPA supplicant to increase overall minimum cyber security level. Corrections in 5.51.5.1 since 5.51.5 ==================================== 5.51.5.1:C01 Corrected an issue that caused the action engine to respawn on scheduled triggered action events. 5.51.5.1:C02 Corrected an issue that caused SD cards to become full and write protected on rare occasions. Corrections in 5.51.5 since 5.50.3.10 ===================================== 5.51.5:C01 Updated R2 GlobalSign Root Certificate to version 20170717. 5.51.5:C02 Corrected an issue that let the camera become unresponsive in rare occasions when connected to an AVHS system. 5.51.5:C03 Corrected critical vulnerability ACV-128401. Known Bugs/Limitations ====================== 5.51.6.1:L01 The camera can not play an audio clip while a viewer is sending/receiving audio from to/from the camera. 5.51.6.1:L02 When the automatic IR cut filter enables/disables the IR cut filter, it may trigger motion detection. 5.51.6.1:L03 Automatic IR Cut Filter will not work if Auto Iris is off. 5.51.6.1:L04 To be able to use all parts of the image in a View Area use the same Aspect Ratio for the View Area as the configured Capture Mode has. For example, when using 1080p mode, assure your view area has 16:9 aspect ratio to be able to define it starting with upper left corner. When a Capture Mode with 4:3 aspect ratio is used, use 4:3 aspect ratio of the View Area. 5.51.6.1:L05 Recording streams to SD Card with a total bit rate above 12Mbit/sec may cause missing frames/sequences. 5.51.6.1:L06 90 and 270 rotation can cause a drop in frame rate. 5.51.6.1:L07 Multiple simultaneous recordings to SD cards and network shares can degrade the performance of the system. 5.51.6.1:L08 Windows Network Shares do not handle all modifiers e.g. %c, since modifiers are UNIX standard. 5.51.6.1:L09 If max gain is set to a low value, e.g. 0, the IR cut filter may not switch back on automatically. 5.51.6.1:L10 When Guard Tour is active, it is not possible to use PTZ controls with Viewer access rights. 5.51.6.1:L11 Frame Size Control does not affect the size of the snapshot taken with the upper right control that can be added to the Live View. 5.51.6.1:L12 If the device has ongoing continuous recordings and the device is restarted using the restart option in web interface, the current part of recordings(block) can not be accessed or downloaded through the web interface. 5.51.6.1:L13 Stream profile names are limited to alphanumerical characters. 5.51.6.1:L14 Recordings made with firmware earlier than 5.20 will not be readable on the SD Card from firmware 5.40 and onward. Backup important recordings and reformat the SD Card after the firmware upgrade. 5.51.6.1:L15 Check and repair is only available if the file system is ext4. 5.51.6.1:L16 The AXIS Media Control client may stop displaying the H.264 video stream after the PC has been locked. 5.51.6.1:L17 Live view does not work with QuickTime player using default settings. Workaround: Disable Direct3D acceleration in Quicktime. 5.51.6.1:L18 When using an action rule results in short recordings, it is recommended to extend post-event time. 5.51.6.1:L19 To avoid corrupt recordings, it is recommended to unmount the SD Card before ejecting it. 5.51.6.1:L20 For actions based on PTZ events, it is not possible to use the #P (PTZ preset name) and #p (PTZ preset number) modifiers in the file names for network share uploads. 5.51.6.1:L21 It's not recommended to downgrade to previous firmware when having HTTPS enabled. 5.51.6.1:L22 Video overlay text size is a global setting and can not be set for each stream profile. 5.51.6.1:L23 Modifying a PTZ view area using API and afterwards clicking save in the web interface, will cause the view area to revert to the old position. 5.51.6.1:L24 The pan control bar on the Live View page is not 100% accurate when clicking on a position. In order to achieve full accuracy, use the arrows to navigate. 5.51.6.1:L25 If text overlay is more than 460 characters long, no text will be displayed. 5.51.6.1:L26 Private keys need to be in a PKCS#1 format in order to function. 5.51.6.1:L27 A maximum of 100 installed certificates is allowed 5.51.6.1:L28 For low contrast scenes, false positives or negatives may occur because there is not enough information for the Tampering alarm. 5.51.6.1:L29 The resolutions of the pre-defined profiles have changed. Quality, Balanced and Bandwidth uses default resolution, which is equal to the highest available resolution. Mobile uses the lowest resolution. 5.51.6.1:L30 If downgrading to previous firmware version, a factory default is recommended after performing the downgrade. 5.51.6.1:L31 Using control queue with Java Applet may result in wrong queue positions if switching between admin and viewer users. 5.51.6.1:L32 GOV values for stream profiles higher than 5000 are not supported. 5.51.6.1:L33 On Windows shares, upload paths for events needs to be created on the share before use. 5.51.6.1:L34 Not possible to view live or recorded video in Internet Explorer 10 Modern UI in Microsoft Windows 8. 5.51.6.1:L35 The Audio tab web page indicates loading until moving to a different tab or page. 5.51.6.1:L36 Reboot is necessary after enabling SOCKS. 5.51.6.1:L37 With audio enabled, setting GOV lengths with I-frames more than 20 seconds apart may render the recordings unplayable via the web interface. 5.51.6.1:L38 When changing active https-certificate, the device needs to be restarted before it becomes active. 5.51.6.1:L39 Upgrading from firmware 5.40 and prior requires an upgrade of the recordings database. This can take up to five minutes and is conducted on first boot. Make sure to not remove power or SD card during the first five minutes after upgrading the device. 5.51.6.1:L40 Unclear error message when uploading audio clip with already existing name. 5.51.6.1:L41 Occasionally, G711 audio can lag when using Java applet. 5.51.6.1:L42 Embedded Motion Detection: When object size is set to low and sensitivity set to high, motion detection can occasionally be triggered when switching the IR filter on/off. Supported AXIS VAPIX API Image Resolutions for AXIS P3346 ========================================================= Resolution Exceptions ========== ========== 2048x1536 2) 1920x1200 2) 1920x1080 2) 3) 1600x1200 2) 4) 1280x1024 1280x960 1280x720 1024x768 800x600 800x450 640x480 640x360 480x360 480x270 320x240 320x180 240x180 176x144 160x120 160x90 1440x900 1) 768x576 1) 704x576 1) 704x480 1) 704x288 1) 704x240 1) 384x288 1) 352x288 1) 352x240 1) 240x135 1) 192x144 1) 176x120 1) 1) Not visible in web user interface 2) 3 MP 2048x1536 (4:3) @ 20fps 3) HDTV 1080p 1920x1080 (16:9) @ 30fps 4) 2 MP 1600x1200 (4:3) @ 30fps